• About Us
  • Contact Us
  • Cookie policy (EU)
  • Home
  • Privacy Policy
  • Video
  • Write for us
Today Headline
  • HOME
  • NEWS
    • POLITICS
    • News for today
    • Borisov news
  • FINANCE
    • Business
    • Insurance
  • Video
  • TECHNOLOGY
  • ENTERPRISE
  • LIFESTYLE
    • TRAVEL
    • HEALTH
    • ENTERTAINMENT
  • AUTOMOTIVE
  • SPORTS
  • Travel and Tourism
  • HOME
  • NEWS
    • POLITICS
    • News for today
    • Borisov news
  • FINANCE
    • Business
    • Insurance
  • Video
  • TECHNOLOGY
  • ENTERPRISE
  • LIFESTYLE
    • TRAVEL
    • HEALTH
    • ENTERTAINMENT
  • AUTOMOTIVE
  • SPORTS
  • Travel and Tourism
No Result
View All Result
TodayHeadline
No Result
View All Result

Fourteen new types of attacks on web browsers detected

December 3, 2021
in Technology
0
Fourteen new types of attacks on web browsers detected
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter


14 new attacks on web browsers detected

Using the XSinator.com tool, the researchers analysed numerous combinations of browsers and operating systems for their vulnerability to XS-Leaks. Credit: RUB, Marquard

IT security experts have identified 14 new types of attacks on web browsers that are known as cross-site leaks, or XS-Leaks. Using XS-Leaks, a malicious website can grab personal data from visitors by interacting with other websites in the background. The researchers from Ruhr-Universität Bochum (RUB) and Niederrhein University of Applied Sciences tested how well 56 combinations of browsers and operating systems are protected against 34 different XS-Leaks.

To this end, they developed the website XSinator.com, which allowed them to automatically scan browsers for these leaks. Popular browsers such as Chrome and Firefox, for example, were vulnerable to a large number of XS-Leaks. “XS-Leaks are often browser bugs that have to be fixed by the manufacturer,” says Lukas Knittel, one of the Bochum authors of the paper.

The researchers published their findings online and at the ACM Conference on Computer and Communications Security, which was held as a virtual event in mid-November 2021. At the conference, Lukas Knittel, Dr. Christian Mainka, Dominik Noß and Professor Jörg Schwenk from the Horst Görtz Institute for IT-Security at RUB as well as Professor Marcus Niemietz from the Niederrhein University of Applied Sciences received a Best Paper Award for their study. The study took place within the Cluster of Excellence “CASA—Cyber Security in the Age of Large-Scale Adversaries.”

How XS-Leaks work

XS-Leaks bypass the so-called same-origin policy, one of a browser’s main defenses against various types of attacks. The purpose of the same-origin policy is to prevent information from being stolen from a trusted website. In the case of XS-Leaks, attackers can nevertheless recognize individual details of a website. If these details are tied to personal data, those data can be leaked. For example, emails in a webmail inbox could be read from a malicious site, because the search function would respond in a different way depending on whether there were results for a search term or not.

In order to systematically analyze XS-Leaks, the group first identified three characteristics of such attacks. Based on these, they then derived a formal model that aids in understanding XS-Leaks and helps in detecting new attacks. As a result, the researchers identified 14 new attack categories.


Two new attacks break PDF certification


More information:
XSinator.com: From a Formal Model to the Automatic Evaluation of Cross-Site Leaks in Web Browsers, PDF: xsinator.com/paper.pdf

Provided by
Ruhr-Universitaet-Bochum

Citation:
Fourteen new types of attacks on web browsers detected (2021, December 2)
retrieved 2 December 2021
from https://techxplore.com/news/2021-12-fourteen-web-browsers.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

Tags: attacksbrowsersdetectedFourteentypesweb
Previous Post

Medicaid expansion is linked with reductions in mortality, according to new research

Next Post

Unite to cut donations to Labour Party

Related Posts

Is propane a solution for more sustainable air conditioning?
Technology

Is propane a solution for more sustainable air conditioning?

Credit: Pixabay/CC0 Public Domain Current...

Read more
Solid-state memory in neuromorphic circuits
Technology

Solid-state memory in neuromorphic circuits

Schematic connection of two biological...

Read more
Open-source software gives a leg up to robot research
Technology

Open-source software gives a leg up to robot research

Quad-SDK is an open-source, full-stack...

Read more
AI-designed camera only records objects of interest while being blind to others
Technology

AI-designed camera only records objects of interest while being blind to others

Object class-specific imaging using a...

Read more
A symmetric unicycle with jumping reaction wheels
Technology

A symmetric unicycle with jumping reaction wheels

Credit: Geist et al. Researchers...

Read more
Load More
Next Post

Unite to cut donations to Labour Party

  • Trending
  • Comments
  • Latest
Collapsed Doggy sex position promises clitoral stimulation for extra pleasure

Collapsed Doggy sex position promises clitoral stimulation for extra pleasure

Who are Liz Cheney’s children?

Six times actors really romped in sex scenes that make 365 DNI look tame

Six times actors really romped in sex scenes that make 365 DNI look tame

Do Sex Dolls Feel Real? – Answering Important Questions 

Karine Jean-Pierre gives update on Biden's 2024 intentions, monkeypox and more

What does verified mean on TikTok and how do I get the badge?

What does verified mean on TikTok and how do I get the badge?

Paysafe Limited (PSFE) CEO Philip McHugh on Q2 2021 Results – Earnings Call Transcript

ZTO Express (Cayman) Inc. 2022 Q2 – Results – Earnings Call Presentation (NYSE:ZTO)

Anthony Joshua vs Oleksandr Usyk, Joshua vs Usyk 2, news, preview, how to watch, start time Australia

Anthony Joshua vs Oleksandr Usyk, Joshua vs Usyk 2, news, preview, how to watch, start time Australia

About Us

Todayheadline the independent news and topics discovery
A home-grown and independent news and topic aggregation . displays breaking news linking to news websites all around the world.

Follow Us

Latest News

Karine Jean-Pierre gives update on Biden's 2024 intentions, monkeypox and more

What does verified mean on TikTok and how do I get the badge?

What does verified mean on TikTok and how do I get the badge?

Karine Jean-Pierre gives update on Biden's 2024 intentions, monkeypox and more

What does verified mean on TikTok and how do I get the badge?

What does verified mean on TikTok and how do I get the badge?

Paysafe Limited (PSFE) CEO Philip McHugh on Q2 2021 Results – Earnings Call Transcript

ZTO Express (Cayman) Inc. 2022 Q2 – Results – Earnings Call Presentation (NYSE:ZTO)

  • Real Estate
  • Education
  • Parenting
  • Cooking
  • NFL Games On TV Today
  • Travel and Tourism
  • Home & Garden
  • Pets
  • Privacy & Policy
  • Contact
  • About

© 2021 All rights are reserved Todayheadline

No Result
View All Result
  • Real Estate
  • Education
  • Parenting
  • Cooking
  • NFL Games On TV Today
  • Travel and Tourism
  • Home & Garden
  • Pets
  • Privacy & Policy
  • Contact
  • About

© 2021 All rights are reserved Todayheadline

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist